This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org
Deletion log
Below is a list of the most recent deletions.
(newest | oldest) View (newer 50 | older 50) (20 | 50 | 100 | 250 | 500)- 09:42, 29 June 2016 Jmanico (talk | contribs) deleted page Implement interface contracts (content was: "{{Template:SecureSoftware}} ==Overview== Purpose: * Provide unit-level semantic input validation. * Identify reliability errors in a structured way at the earliest point in time. Role: * Implementer Frequency: * As needed; gene...")
- 09:42, 29 June 2016 Jmanico (talk | contribs) deleted page Implement and elaborate resource policies and security technologies (content was: "{{Template:SecureSoftware}} ==Overview== Purpose: * Implement security functionality to specification Role: * Implementer Frequency: * As necessary ==Review specified behavior == The developer should identify any remaining am...")
- 09:42, 29 June 2016 Jmanico (talk | contribs) deleted page Category:CLASP Best Practice (content was: "{{Template:SecureSoftware}} ==Best Practices== #Institute awareness programs #:Category:BP2 Perfo..." (and the only contributor was "Pravir Chandra"))
- 09:41, 29 June 2016 Jmanico (talk | contribs) deleted page Category:BP3 Capture security requirements (content was: "==Overview== Ensure that security requirements have the same level of “citizenship” as all other “must haves.” It’s easy for application architects and project managers to focus on functionality when defining requirements, sinc...")
- 09:41, 29 June 2016 Jmanico (talk | contribs) deleted page Category:BP4 Implement secure development practices (content was: "==Overview== Defined security activities, artifacts, guidelines and continuous reinforcement should become part of your organization’s overall cul..." (and the only contributor was "Pravir Chandra"))
- 09:41, 29 June 2016 Jmanico (talk | contribs) deleted page Identify user roles and resource capabilities (content was: "{{Template:SecureSoftware}} ==Overview== Purpose: * Define system roles and the capabilities/resources that the role can access. Role: * Architect Frequency: * As necessary; generally, once per iteration. ==Identify distinct c...")
- 09:41, 29 June 2016 Jmanico (talk | contribs) deleted page Identify resources and trust boundaries (content was: "{{Template:SecureSoftware}} ==Overview== Purpose: * Provide a structured foundation for understanding the security requirements of a system. Role: * Architect Frequency: * As necessary; generally, once per iteration. ==Identif...")
- 09:41, 29 June 2016 Jmanico (talk | contribs) deleted page Identify global security policy (content was: "{{Template:SecureSoftware}} ==Overview== Purpose: * Provide default baseline product security business requirements. * Provide a way to compare the security posture of different products across an organization. Role: * Requirement...")
- 09:41, 29 June 2016 Jmanico (talk | contribs) deleted page Identify attack surface (content was: "{{Template:SecureSoftware}} ==Overview== Purpose: * Specify all entry points to a program in a structured way to facilitate analysis. Role: * Designer Frequency: * As needed; usually once after design, and ongoing during elaborat...")
- 09:40, 29 June 2016 Jmanico (talk | contribs) deleted page Category:Authentication (content was: "==Overview== In most cases, one wants to establish the identity of either a communications partner or the owner, creator, etc. of data. For network connections, it is important to perform authentication at login time, but it is also imp...")
- 09:40, 29 June 2016 Jmanico (talk | contribs) deleted page Slow Down Online Guessing Attacks with Device Cookies (content was: "Category:ControlCategory:Authentication ==Intro== Device cookies as additional authenticator for users devices have been discussed and used in practice for..." (and the only contributor was "Adedov"))
- 09:40, 29 June 2016 Jmanico (talk | contribs) deleted page Parola secreta? (content was: "==Using Secret Questions== To help verify a user's identity in the case of a lost password, many Web applications use secret questions. By answering a pre-selected question, a user can demonstrate some personal knowledge of the account...")
- 09:40, 29 June 2016 Jmanico (talk | contribs) deleted page Guide to Authentication (content was: "{{taggedDocument | type=inactiveDraft | comment=Most content from 2008/2009 with one positive exception in 2014. Please consider the Authentication Cheat Sheet instead. }} Guide Table of Contents|Development Guide Table of Content...")
- 09:40, 29 June 2016 Jmanico (talk | contribs) deleted page Comprehensive list of Threats to Authentication Procedures and Data (content was: "=== Background === There is a bewildering array of tricks, techniques, and technologies that exist to steal passwords, attack password systems, and circumvent authenticat..." (and the only contributor was "Cnd"))
- 09:40, 29 June 2016 Jmanico (talk | contribs) deleted page Authentication In IIS (content was: "==Authentication in IIS== We often think about security measures as ways of protecting resources by preventing access to them. The need for authentication arises because, in the real world, keeping people out of protected areas is only...")
- 09:39, 29 June 2016 Jmanico (talk | contribs) deleted page Relative path library search (content was: "{{Template:Vulnerability}} {{Template:SecureSoftware}} '''Last revision (mm/dd/yy): '''{{REVISIONMONTH}}/{{REVISIONDAY}}/{{REVISIONYEAR}}''' Vulnerabilities Table of Contents ==Description== Certain func...")
- 09:39, 29 June 2016 Jmanico (talk | contribs) deleted page Reflection attack in an auth protocol (content was: "{{Template:Vulnerability}} {{Template:SecureSoftware}} Vulnerabilities Table of Contents ==Description== Simple authentication protocols are subject to reflection attacks if a malicious user can use the ta...")
- 09:39, 29 June 2016 Jmanico (talk | contribs) deleted page Reflection injection (content was: "{{Template:Vulnerability}} Last revision (mm/dd/yy): '''{{REVISIONMONTH}}/{{REVISIONDAY}}/{{REVISIONYEAR}}''' Categorie:FIXME/merge https://www.owasp.org/index.php/Unsafe_use_of_Reflection == Description == Reflection injection p...")
- 09:38, 29 June 2016 Jmanico (talk | contribs) deleted page Reliance on data layout (content was: "{{Template:Vulnerability}} {{Template:SecureSoftware}} Last revision (mm/dd/yy): '''{{REVISIONMONTH}}/{{REVISIONDAY}}/{{REVISIONYEAR}}''' Vulnerabilities Table of Contents ==Description== Assumptions abou...")
- 09:38, 29 June 2016 Jmanico (talk | contribs) deleted page Relying on package-level scope (content was: "{{Template:Vulnerability}} {{Template:SecureSoftware}} Last revision (mm/dd/yy): '''{{REVISIONMONTH}}/{{REVISIONDAY}}/{{REVISIONYEAR}}''' Vulnerabilities Table of Contents ==Description== Java packages ar...")
- 09:38, 29 June 2016 Jmanico (talk | contribs) deleted page Resource exhaustion (content was: "{{Template:Vulnerability}} {{Template:SecureSoftware}} Last revision (mm/dd/yy): '''{{REVISIONMONTH}}/{{REVISIONDAY}}/{{REVISIONYEAR}}''' Vulnerabilities Table of Contents ==Description== Resource exhaust...")
- 09:38, 29 June 2016 Jmanico (talk | contribs) deleted page Reusing a nonce, key pair in encryption (content was: "{{Template:Vulnerability}} {{Template:SecureSoftware}} Last revision (mm/dd/yy): '''{{REVISIONMONTH}}/{{REVISIONDAY}}/{{REVISIONYEAR}}''' Vulnerabilities Table of Contents ==Description== Nonces should be...")
- 09:19, 29 June 2016 Jmanico (talk | contribs) deleted page Research and assess security posture of technology solutions (content was: "{{Template:SecureSoftware}} ==Overview== Purpose: * Assess security risks in third-party components. * Determine how effective a technology is likely to be at alleviating risks. Role: * Designer Frequency: * As necessary. ==G...")
- 09:19, 29 June 2016 Jmanico (talk | contribs) deleted page Identify, implement, and perform security tests (content was: "{{Template:SecureSoftware}} ==Overview== Purpose: * Find security problems not found by implementation review. * Find security risks introduced by the operational environment. * Act as a defense-in-depth mechanism, catching failur...")
- 09:18, 29 June 2016 Jmanico (talk | contribs) deleted page Category:BP2 Perform application assessments (content was: "==Overview== While it’s true that you cannot test security into an application, application testing and assessments should still be a central comp..." (and the only contributor was "Pravir Chandra"))
- 09:18, 29 June 2016 Jmanico (talk | contribs) deleted page Institute security awareness program (content was: "{{Template:SecureSoftware}} ==Overview== Purpose: *Ensure project members consider security to be an important project goal through training and accountability. *Ensure project members have enough exposure to security to deal with i...")
- 09:18, 29 June 2016 Jmanico (talk | contribs) deleted page Category:BP1 Institute awareness programs (content was: "==Overview== Essential security concepts and techniques may be foreign to your organization’s software developers and others involved in applicati..." (and the only contributor was "Pravir Chandra"))
- 09:18, 29 June 2016 Jmanico (talk | contribs) deleted page Category:BP7 Publish operational security guidelines (content was: "==Overview== Security does not end when an application is completed and deployed in a production environment. Making the most out of existing network and operational security investments requires that you inform and educate those tasked...")
- 09:18, 29 June 2016 Jmanico (talk | contribs) deleted page Category:BP6 Define and monitor metrics (content was: "==Overview== You cannot manage what you cannot measure. Unfortunately, implementing an effective metrics monitoring effort can be a difficult undertaking. Despite this, metrics are an essential element of your overall application securit...")
- 09:18, 29 June 2016 Jmanico (talk | contribs) deleted page Category:BP5 Build vulnerability remediation procedures (content was: "==Overview== It is especially important in the context of application updates and enhancements to define which steps will be taken to identify, asse..." (and the only contributor was "Pravir Chandra"))
- 09:18, 29 June 2016 Jmanico (talk | contribs) deleted page Category:Confidentiality (content was: "{{Template:SecureSoftware}} ==Confidentiality== It is often a requirement that data should be secret to all unauthorized parties, both when in transit on a network and when being stored, long-term or short-term. Confidentiality is oft...")
- 09:17, 29 June 2016 Jmanico (talk | contribs) deleted page Category:CLASP Role (content was: "{{Template:SecureSoftware}} Category:OWASP CLASP Project ==Overview== This section contains role-based introductions to the CLASP method and pr..." (and the only contributor was "Pravir Chandra"))
- 09:17, 29 June 2016 Jmanico (talk | contribs) deleted page Implementer (content was: "{{Template:SecureSoftware}} ==Role Description== Traditionally, application development is handled in an ad-hoc manner, and it is the implementer who must carry the bulk of the security expertise. Ultimately, this is because — in ad-h...")
- 09:17, 29 June 2016 Jmanico (talk | contribs) deleted page Requirements Specifier (content was: "{{Template:SecureSoftware}} ==Role Description== The requirements specifier has these major tasks: * He is first responsible for detailing business requirements that are security relevant, particularly those things that will need to be...")
- 09:09, 29 June 2016 Jmanico (talk | contribs) restored page HTTP Response Splitting (35 revisions restored: deleted to quickly)
- 09:08, 29 June 2016 Jmanico (talk | contribs) deleted page Signed to unsigned conversion error (content was: "{{Template:Vulnerability}} {{Template:SecureSoftware}} Vulnerabilities Table of Contents ==Description== A signed-to-unsigned conversion error takes place when a signed primitive is used as an unsigned valu...")
- 09:08, 29 June 2016 Jmanico (talk | contribs) deleted page Sign extension error (content was: "{{Template:Vulnerability}} {{Template:SecureSoftware}} Vulnerabilities Table of Contents ==Description== If one extends a signed number incorrectly, if negative numbers are used, an incorrect extension may...")
- 09:07, 29 June 2016 Jmanico (talk | contribs) deleted page Security Auditor (content was: "{{Template:SecureSoftware}} ==Role Description== The basic role of a security auditor is to examine the current state of a project and try to assure the security of the current state of the project: * When examining requirements, the au...")
- 09:07, 29 June 2016 Jmanico (talk | contribs) deleted page Failure of true random number generator (content was: "{{taggedDocument | type=inactiveDraft }} {{Template:Vulnerability}} {{Template:SecureSoftware}} <!-- Last revision hardcoded to 03/6/2009 on 04/Nov/2014 because: page source formaly changed (category) but no content changed, whi...")
- 09:06, 29 June 2016 Jmanico (talk | contribs) deleted page Specify database security configuration (content was: "{{Template:SecureSoftware}} ==Overview== Purpose: * Define a secure default configuration for database resources that are deployed as part of an implementation. * Identify a recommended configuration for database resources for datab...")
- 09:06, 29 June 2016 Jmanico (talk | contribs) deleted page Specify operational environment (content was: "{{Template:SecureSoftware}} ==Overview== Purpose: * Document assumptions and requirements about the operating environment, so that the impact on security can be assessed. Role: * Requirements Specifier Frequency: * As necessary;...")
- 09:06, 29 June 2016 Jmanico (talk | contribs) deleted page Stack overflow (content was: "{{Template:Vulnerability}} {{Template:SecureSoftware}} Vulnerabilities Table of Contents ==Description== A stack overflow condition is a buffer overflow condition, where the buffer being overwritten is al...")
- 09:06, 29 June 2016 Jmanico (talk | contribs) deleted page State synchronization error (content was: "{{Template:Vulnerability}} {{Template:SecureSoftware}} Vulnerabilities Table of Contents ==Description== State synchronization refers to a set of flaws involving contradictory states of execution in a proc...")
- 09:06, 29 June 2016 Jmanico (talk | contribs) deleted page Storing passwords in a recoverable format (content was: "{{Template:SecureSoftware}} {{Template:Vulnerability}} Last revision (mm/dd/yy): '''{{REVISIONMONTH}}/{{REVISIONDAY}}/{{REVISIONYEAR}}''' Vulnerabilities Table of Contents ==Description== The storage of pa...")
- 09:06, 29 June 2016 Jmanico (talk | contribs) deleted page Symbolic name not mapping to correct object (content was: "{{Template:Vulnerability}} {{Template:SecureSoftware}} Last revision (mm/dd/yy): '''{{REVISIONMONTH}}/{{REVISIONDAY}}/{{REVISIONYEAR}}''' Vulnerabilities Table of Contents ==Description== A constant symbol...")
- 09:04, 29 June 2016 Jmanico (talk | contribs) deleted page Category:OWASP CLASP Project (content was: "{| |- ! width="700" align="center" | <br> ! width="500" align="center" | <br> |- | align="right" | link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Inactive_Projects | align="righ...")
- 09:01, 29 June 2016 Jmanico (talk | contribs) deleted page Publicizing of private data when using inner classes (content was: "{{Template:Vulnerability}} {{Template:SecureSoftware}} Last revision (mm/dd/yy): '''{{REVISIONMONTH}}/{{REVISIONDAY}}/{{REVISIONYEAR}}''' Vulnerabilities Table of Contents ==Description== Java byte code...")
- 09:01, 29 June 2016 Jmanico (talk | contribs) deleted page Project Manager (content was: "{{Template:SecureSoftware}} ==Role Description== Software security efforts are rarely successful without buy-in from the project manager. In most organizations, security will not be a concern to individual project members if left to the...")
- 09:01, 29 June 2016 Jmanico (talk | contribs) deleted page Perform source-level security review (content was: "{{Template:SecureSoftware}} ==Overview== Purpose: * Find security vulnerabilities introduced into implementation. Role: * Security Auditor Frequency: * Incrementally, at the end of each implementation iteration. ==Scope the en...")
- 09:01, 29 June 2016 Jmanico (talk | contribs) deleted page Perform security analysis of system requirements and design (threat modeling) (content was: "{{Template:SecureSoftware}} ==Overview== Purpose: * Assess likely system risks in a timely and cost-effective manner by analyzing the requirements and design. * Identify high-level system threats that are documented neither in requi...")